# Gated independent pilot onboarding packet

Entry URL: https://gated-git-codex-gated-gith-4948e4-jasperdevelops-7362s-projects.vercel.app/console#view=onboarding

Version: 17 September 2026. Private staging pilot; non-critical GitHub branch creation only. This packet is preparation, not evidence that an independent tester has completed onboarding.

## Before starting

Agree the test scope, support, observation, retention and recovery limits with Jasper Dragoo at support@gated.sh. There is no staffed support team or guaranteed response time. Bring an email account you can access, a supported browser and passkey authenticator, Node 24, and Codex or Claude Code (or the explicit CLI path for Cursor below). You must administer a disposable/non-critical GitHub repository with an existing commit. No sensitive customer or production data.

**Repository preflight, before signup:** open your chosen repository on GitHub, confirm it has a branch with a commit, and copy the full 40-character commit SHA. An empty repository cannot pass this pilot. Choose an already initialized repository. Do not invent a SHA or ask the test agent to create the first commit outside Gated. If the owner chooses to initialize a repository separately, record that as preparation before a new attempt.

The exercise creates one uniquely named branch at an exact commit. GitHub App Contents write is broader than this operation. Direct GitHub credentials can bypass Gated; installing the skill does not intercept every tool. AWS and Vercel actions are outside the pilot. Backups exist, but full replacement-service recovery has been deferred until a separate server is ready; the scheduled backup capture/encryption/readback/archive check passed on 14 September 2026 (GitHub Actions run 34825372285). This does not prove full replacement recovery.

The operator should observe without coaching. Ask naturally when stuck; record every question and any assistance. Stop rather than work around a denied request, uncertain execution, or permission mismatch. Do not give the operator passwords, tokens, authenticator codes or recovery keys.

## Attempt the workflow

1. Open the entry URL. Create and confirm your account, then sign in. Alternatively use the offered GitHub or Google sign-in. Create a fresh workspace so old activity cannot satisfy this rehearsal’s milestones. Open Pilot setup. The initial policy denies all actions.
2. Open Account security. Enroll a passkey and a second independently usable authenticator. If you enable an authenticator app, keep its recovery material privately and enter its code when signing in. Passkeys authorize sensitive actions; an authenticator-app code does not replace approval of a particular request.
3. Open Connect GitHub. Install Gated Approval Proof on only your chosen repository. Complete the passkey and GitHub authorization, choose your repository from the verified picker, and click **Connect repository**. The GitHub authorization banner only confirms App access; it is not a saved Gated connection. Confirm the repository appears under Connected repositories with its `github:<number>` resource ID. New connections check for an existing branch before saving. If you installed the App after authorizing, refresh GitHub access. Repositories bound to another workspace are disabled. No automatic transfer is supported: an administrator must remove the existing connection, then you can refresh the list and reconnect with current GitHub access. Record the displayed repository resource ID (github:<number>) and workspace ID. A failed or ambiguous connection is not a successful milestone.
4. Open Agents & tokens. Create a short-lived agent token restricted to that repository and github.branch.create. Keep the token private for the protected session in step 6; do not paste it into an agent prompt, committed file, transcript or shell history.
5. After creating the agent, use Pilot setup to generate its starter policy and open Policies. Save an approval-required rule for github.branch.create, only the connected repository resource, and only the new agent. The current schema labels this operation’s environment “production”; this is a request classification, not permission to use a critical production repository. Use your non-critical repository. Never enable a broad allow rule to avoid an approval. In the builder, select the agent and repository and leave Strict checked, then choose **Use these rules in editor** and **Save policy**. The first button prepares a draft; it does not save. Alternatively, copy the complete generated JSON rules array exactly as shown into the Advanced policy editor and save; do not apply both paths redundantly. The editor expects an array ([…]), without a {"rules": …} wrapper. Check that saving succeeds.
6. In Pilot setup, download and review both the self-contained installer and shell preflight linked there. Save them in the same directory. The preflight supports macOS/Linux and checks Node 24, the executable, installer path, and existing project. If Node is missing or wrong, follow its exact instructions and retry; it never installs Node for you. Run ONE matching command against your pilot checkout:

   sh gated-agent-preflight.sh ./gated-agent-setup.mjs codex /absolute/path/to/pilot-project

   sh gated-agent-preflight.sh ./gated-agent-setup.mjs claude-code /absolute/path/to/pilot-project

   The installer refuses to overwrite an existing skill. From the project directory, run the exact protected-session command shown in Pilot setup and paste the scoped token at its hidden prompt. A successful check opens a shell; launch your coding client there. In Codex invoke $gated-github; in Claude Code invoke /gated-github. Supply the repository resource ID, an exact existing 40-character commit SHA, a unique branch such as gated/pilot-20260914-unique-suffix, and a short non-sensitive intent. No direct GitHub token is needed by this skill.
7. Have the skill submit the request. Keep its original request file for status and replay. Submission must be within five minutes of preparing it. In Approvals, inspect the exact repository, branch, SHA and policy before approving with a passkey. Approval alone does not create the branch. Ask the agent to execute the same saved request after approval.
8. Check the returned result and Action Graph. SIMULATED means no provider write. SUBMITTED means the provider returned the expected branch/SHA response; independently open GitHub and check that exact branch and commit. UNKNOWN or a timeout requires operator reconciliation, not a new request or direct GitHub write. Inspect Operations for cleanup or monitoring warnings. Record sanitized request/execution IDs, never tokens or full task context.
9. In Pilot setup, refresh and download the milestone report. It reuses existing timestamps; the account timestamp is yours and the other events are workspace-wide. It is not a session recording or proof that you worked without help. An automatic or saved empty policy, unrelated or ALLOW-only policy, denied approval, simulated execution or uncertain execution does not complete the corresponding GitHub-approval-policy/approval/live-action milestone. The policy timestamp is its first qualifying archived version; it is historical, not a guarantee that the current policy matches every future request.
10. Revoke the test agent. The same token should then be rejected. Preserve the audit and test evidence. Do not delete the workspace or ask Gated to delete the test branch; branch deletion is not implemented. Agree any later repository cleanup with its owner.

## What to report

Tell the operator where wording was unclear, where you hesitated, where a step failed, how you understood the requested permissions, and when you needed help. Share only the milestone report and sanitized IDs needed for diagnosis. Use privacy@gated.sh for export/deletion requests and security@gated.sh for security reports.

A Cursor/other-agent run with owner interventions is an **agent-assisted rehearsal**. It can expose defects and verify technical behavior, but does not establish independent human usability.

Passing the independent usability rehearsal requires an independent developer to attempt the workflow without live coaching. An operator-run or separate-account internal test cannot meet that exit condition. Record independent GitHub readback separately from the automated live-response milestone.

## Client setup check and recovery

Download the installer and shell preflight from Pilot setup into the same folder. Run the displayed preflight with an existing project folder (or create `~/gated-pilot` first with `mkdir -p ~/gated-pilot`). It checks macOS/Linux, Git, Node 24, the installer syntax and canonical paths. If Node is missing or old, install Node 24 LTS using the official installer at https://nodejs.org/en/download, reopen the terminal and rerun. Standard macOS Node locations are checked even if PATH is missing. `GATED_NODE=/absolute/path/to/node` is supported only when you deliberately choose an existing installation. No private application runtime is required.

From the project folder, copy the exact protected-session command in Pilot setup. Paste the scoped Gated token at its hidden prompt. The launcher checks the API and token/workspace, opens a shell with a `gated` command, and keeps the token in that process environment only. Run `gated doctor` to repeat validation; launch Codex or Claude Code from that shell so it inherits the same environment. Type `exit` when finished. Never echo the token or environment. Automated clients may inject the three Gated variables through a protected process environment instead. Invalid/revoked tokens fail before any action; obtain a fresh scoped token through the normal console flow.

## Signup email recovery

For a fresh-account rehearsal, use an address that has never been registered with Gated. A disposable inbox left open from an earlier test may still belong to an already verified Gated account. An accepted signup request does not prove a message was sent or delivered. For pending verification, check inbox and spam and enter the latest code. Already verified addresses should sign in: repeating signup or requesting another confirmation does not send them a new signup code. Gated does not disclose account existence in its signup response. Resend becomes available after 60 seconds; signup and resend share per-address limits. An expired code needs a new resend. If email still does not arrive, verify the address and contact support without sharing codes or passwords.

## Returning from GitHub

If identity verification expires while at GitHub, the isolated callback page can request a fresh passkey and continue the same unused callback while its original five-minute state is valid. No security lifetime is extended. An expired/used state, new or expired Gated session, or lost workspace access requires returning to Gated and checking Connections before starting again. Complete GitHub sign-in/account approval if GitHub asks. Repository access is checked again when binding.

## Cursor or another client: explicit CLI path

Use the `codex` installer option above to place the CLI under `.agents/skills/gated-github`; this is a filesystem layout, not a claim that Cursor loads Codex skills. Open the protected session from Pilot setup. Run `gated doctor`, then use the bundled CLI directly. Supply the real resource ID, existing full SHA and unique branch; never paste the token into a prompt.

Create a private, untracked directory for the saved request and replace the placeholders below. The runtime value `other` accurately labels this client.

```sh
gated prepare /absolute/private/request.json github:REPO_ID gated/UNIQUE_BRANCH EXISTING_40_CHARACTER_SHA other "Create a non-critical pilot branch"
gated submit /absolute/private/request.json
gated status /absolute/private/request.json
```

Submit within five minutes of preparing. Keep the same file. Wait for the human to approve the exact request in Gated, then:

```sh
gated execute /absolute/private/request.json
```

If your agent does not inherit the shell function, use `node .agents/skills/gated-github/scripts/gated.mjs` in place of `gated`, with the same protected process environment. Follow the original status/reconciliation rules after a timeout; do not prepare a replacement request to retry an uncertain execution.

## Human passkey actions and interruptions

The human should focus the Gated browser tab and personally click Save policy or Approve when identity verification is needed, then complete the browser/OS passkey prompt. An agent click is not proof a prompt appeared. If nothing appears or verification times out, record the failure, check the saved state, and retry the intended action yourself. Never treat a timeout as approval or weaken the policy to continue. If a Vercel preview toolbar dialog covers controls, dismiss it before continuing and record the interruption.
